Cybersecurity at STIEBEL ELTRON
Security is an integral part of our product quality. Our customers depend on STIEBEL ELTRON products every day. That’s why we regard cybersecurity as an essential part of our quality and innovation strategy.
We build security into our products from the start, minimising risks and reliably protecting digital features. We ensure our security measures always meet the latest requirements through continuous improvements and regular reviews.
Responsibility for digital security
Our products’ increasing connectivity is unlocking new opportunities for convenience and energy efficiency. At the same time, the demands on their protection are growing.
STIEBEL ELTRON pursues a holistic approach to security that combines technical, organisational and procedural measures. We aim to ensure the highest possible level of availability, integrity and confidentiality for relevant systems and data.
For general inquiries or feedback regarding cybersecurity, please contact: security@stiebel-eltron.com
Working together for greater security
The cybersecurity community makes an important contribution to improving digital security.
If you have information about potential security vulnerabilities in STIEBEL ELTRON products or digital services, we would be grateful if you could report it responsibly.
Vulnerability reports can be submitted in the following ways:
- Using our security incident and vulnerability reporting form
- Contacting us directly at security@stiebel-eltron.com
Every report is treated confidentially by our security experts and is assessed and processed in accordance with established procedures. We aim to work transparently with you and to promptly assess and resolve legitimate security reports. Further information on the reporting process, the details required in a report and the framework for responsible disclosure can be found in our Vulnerability Disclosure Policy.
STIEBEL ELTRON supports responsible security research. Anyone who acts in accordance with this policy and reports security vulnerabilities responsibly helps to continuously improve the security of our products and services.
Vulnerability Disclosure Policy
1. Our commitment
The security of our products, digital services and connected solutions is a top priority for STIEBEL ELTRON. We develop and operate our products with a focus on ensuring confidentiality, integrity, availability and security for our customers.
At the same time, we are aware that, despite careful development, testing and quality assurance, vulnerabilities cannot be completely ruled out. Feedback from security researchers, customers, partners and third parties helps us to identify, assess and fix potential vulnerabilities in good time.
We therefore welcome responsible reports of potential vulnerabilities under this Vulnerability Disclosure Policy.
2. Purpose
This policy sets out how potential security vulnerabilities can be reported to STIEBEL ELTRON and how we handle such reports.
We aim to ensure the coordinated disclosure of vulnerabilities. This means that any potential vulnerability should first be reported to us confidentially, so we can investigate and assess it and, where necessary, provide appropriate remedial measures (such as security updates, configuration guidance or other protective measures) before any technical details become public knowledge.
3. Scope
This policy applies to any potential security vulnerabilities in STIEBEL ELTRON products, software, firmware, apps, digital interfaces and associated services, insofar as these are provided, operated or managed by STIEBEL ELTRON.
The scope covers, in particular:
- Connected devices and systems from STIEBEL ELTRON
- Software and firmware used in STIEBEL ELTRON products
- Mobile applications and web applications, insofar as they are provided by STIEBEL ELTRON
- Digital interfaces, APIs and communication interfaces
- Cloud or remote functions, where they form part of a STIEBEL ELTRON product or service
- Third-party components, insofar as they are included in STIEBEL ELTRON products or digital solutions
It does not cover third-party systems or services for which STIEBEL ELTRON is not responsible.
4. Reporting vulnerabilities
Security vulnerabilities can be reported in the following ways:
- Using the security form on this website
- Contacting us directly at security@stiebel-eltron.com
Please provide the following information if possible:
- Affected products or services
- Product version
- Description of the vulnerability
- Steps for reproducing the issue
- Potential implications
- Any available screenshots, log files or proof-of-concept evidence
5. How we handle reports
Once we have received a report, we will:
1. Confirm receipt of the report
2. Assess the reported vulnerability
3. Take the necessary countermeasures
4. Keep the vulnerability reporter informed of the status of the report, where possible
5. If necessary, inform the users affected about the vulnerability, as well as any appropriate protective or remedial measures
Vulnerabilities are prioritised according to the respective risk and criticality.
6. Requirements for responsible security research
We ask all reporters to act responsibly, lawfully and with due care when investigating and reporting potential vulnerabilities. Please observe the following in particular:
- Only carry out tests on systems, devices or accounts that you are authorised to access.
- Do not access third-party data, and do not alter, delete or exfiltrate any data.
- Avoid affecting the availability, integrity or security of products, services or networks.
- Do not exploit a potential vulnerability beyond what is necessary for verification purposes.
- Do not publish any technical details before we have had the opportunity to investigate the vulnerability and take appropriate action.
- Refrain from using blackmail, threats or any other forms of undue pressure.
- Observe all applicable legal requirements.
7. Coordinated disclosure
We support the coordinated disclosure of security vulnerabilities. We therefore ask that you allow us sufficient time to examine, assess and, where necessary, rectify the vulnerability before making it public.
Avoid making this information public until:
- We have assessed the vulnerability
- Appropriate remedial measures are in place, or a reasonable date for public disclosure has been agreed
- It has been possible to inform the users concerned, where appropriate
- Statutory reporting or information obligations have been taken into account
If a vulnerability is already being actively exploited or if there is an immediate risk to users, different measures may be required, in particular the accelerated notification of affected individuals or the relevant authorities.
8. Prohibited activities
The following actions are not permitted:
- Access to personal data or confidential information belonging to third parties
- Amendment or deletion of data
- Disruption to the availability of systems or services
- Use of denial-of-service attacks (DoS/DDoS)
- Installation of malicious software
- Social engineering that targets employees, customers or partners
- Physical attacks on facilities or infrastructure
9. Legal measures against reports made in good faith
As a matter of principle, STIEBEL ELTRON will never take legal action against individuals who act in good faith, lawfully and in accordance with this policy, by responsibly reporting a vulnerability.
However, this applies only insofar as the vulnerability reporter:
- Complies with the terms of this policy
- Does not collect, alter, delete, publish or disclose any third-party data without authorisation
- Does not interfere with any systems, products or services
- Does not exploit any vulnerability for their own purposes or to the detriment of third parties
- Does not commit any unlawful acts
- Works with us to handle the report in a coordinated manner
This statement does not constitute a waiver of any rights or claims in respect of any actions taken outside the scope of this policy or in contravention of applicable law.
10. Data protection
Personal data provided in connection with a vulnerability report will be used solely to process the report and communicate with the reporter.
Our privacy policy provides further details.
11. No remuneration or commitment to provide a bug bounty
This policy does not constitute a bug bounty programme, nor does it give rise to any entitlement to remuneration, a reward, reimbursement of expenses or any other form of consideration.
If STIEBEL ELTRON chooses to provide recognition or acknowledgement in individual cases, it will be done voluntarily and only after prior agreement with the reporter.
12. Security updates and user information
Where a reported vulnerability is confirmed, and remedial action is required, STIEBEL ELTRON may take the following measures, in particular:
- Provision of security or firmware updates
- Publication of security advisories
- Provision of workarounds or configuration guidance
- Direct notification of affected users
- Notification of partners, retailers or service providers
- Legally required reports to the relevant authorities
13. Statutory reporting obligations
STIEBEL ELTRON will comply with statutory reporting and disclosure obligations, in particular where a reported vulnerability is classified as an actively exploited vulnerability or as a serious security incident within the meaning of applicable cyber security regulations.
Insofar as is necessary, reports will be made via the appropriate reporting channels or platforms, and affected users will be informed of the risks and any possible protective or remedial measures.
14. Contact
STIEBEL ELTRON Security Team
Email: security@stiebel-eltron.com
Alternatively, you can use our vulnerability reporting form. Please use these contact details exclusively for security-related reports. For general customer service, product advice or technical support inquiries, please use the usual contact details for STIEBEL ELTRON.
Reporting vulnerabilities
Thank you for helping to ensure the security of our products and digital services. Please use the form below to report potential vulnerabilities in accordance with our Vulnerability Disclosure Policy. We treat all reports confidentially and review them as part of our Vulnerability Management Process.
Guidance on submitting a report
Please describe the vulnerability as precisely as possible and (insofar as is lawful and possible without causing harm to third parties) include technical details, steps to reproduce the vulnerability, information on the affected products and versions, and your contact details.
We process reports in accordance with a procedure for the coordinated disclosure of vulnerabilities. Please do not publish any technical details until we have had the opportunity to investigate the vulnerability and provide appropriate protective or remedial measures.
We support genuine, legitimate and responsible security research, provided that it is carried out in accordance with our Vulnerability Disclosure Policy and does not compromise any individuals, data, systems or services.
What happens after you have reported a vulnerability?
1. We confirm receipt of your report
2. Our security team conducts an initial assessment
3. We perform analysis and prioritisation
4. We develop and implement countermeasures
5. We inform you when processing is complete
Closing remarks
Alternatively, you can also report security vulnerabilities directly by email to security@stiebel-eltron.com.
If you choose to do so, please provide as much of the information required on the form as possible. This will allow us to process your inquiry quickly. Please use these contact details exclusively for security-related reports. For general customer inquiries, product advice or technical support inquiries, please use the usual contact details for STIEBEL ELTRON.